Author
Topic: The Race to Zero (Read 1886 times)

The Race to Zero contest is being held during Defcon 16 at the Riviera Hotel in Las Vegas, 8-10 August 2008.

The event involves contestants being given a sample set of viruses and malcode to modify and upload through the contest portal. The portal passes the modified samples through a number of antivirus engines and determines if the sample is a known threat. The first team or individual to pass their sample past all antivirus engines undetected wins that round. Each round increases in complexity as the contest progresses.

There are a number of key ideas we want to get across by running this event:

1. Reverse engineering and code analysis is fun.

2. Not all antivirus is equal, some products are far easier to circumvent than others. Poorly performing antivirus vendors should be called out.

3. The majority of the signature-based antivirus products can be easily circumvented with a minimal amount of effort.

4. The time taken to modify a piece of known malware to circumvent a good proportion of scanners is disproportionate to the costs of antivirus protection and the losses resulting from the trust placed in it.

5. Signature-based antivirus is dead, people need to look to heuristic, statistical and behaviour based techniques to identify emerging threats

6. Antivirus is just part of the larger picture, you need to look at controlling your endpoint devcies with patching, firewalling and sound security policies to remain virus free.

Above all we want the contestants to have fun!

Rules

Rules of Engagement

The following rules apply to all contetants:

1. Contestants can work in teams of up to 4 people

2. Modified virus samples must be functionally the same as the originalYou can modify mutexes, filenames, process names, IP addresses, etc as long as the code functions the same

3. Modified malcode samples must still exploit the vulnerability it was intended forSamples of vulnerable software will be provided to contestants to test their exploits against

4. Modified samples will not be submitted to antivirus vendors unless authorised by contest participants